reserved the 61000-65095 port range, which is the reason why the current default upper limit in ip_local_port_range is 61000. However, the current iptables-based masquerading and SNAT implementation does not have that restriction; ipchains and the compatibilty mode that used the range over 61000 exclusively is lone gone.
                  
                  
                  B: I don't think so, anyone out there using "--to-port 61000-65095" or similar in their firewall setup will suddenly break with your change.
                  
                  
                  A: Do you want me to document where 61000 comes from instead?
                  
                  
                  B: I think the current documentation on this is adequate.
                  
                  
                
 Max
                          Силинг
                        
                      
                    
                    
                    
                    
                      Автор вопроса
                      
                      
                        
                          Max
                          Силинг
                        
                      
                    
                    
                    
                    
                      Автор вопроса
                    
                    
                  ограничения вообще только в ipchain
Ну, судя по цитате выше — похоже, и ип-таблицы внезапно затронуло.
Обсуждают сегодня